A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote ho
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file uplo
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whi
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoo
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromis
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker wh
When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element cl
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS miscon
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the or
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random or
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark
OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in t
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source m
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio
This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are a
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2.
ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to ver
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-contr
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulne
Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call ar
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, ak
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correc
Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of
Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case manag
In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly al
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address t
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code withou
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to sup
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started